bankily.mr Listed by apt73 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
bankily.mr has been listed by the apt73 ransomware group, with internal files reported exfiltrated in the attack. The incident was disclosed on December 09, 2024; an undisclosed number of individuals may be affected, and anyone with an account or prior dealings with the organization should review their exposure and change credentials where appropriate.
People who use or work with the BANKILY mobile banking service in Mauritania may now face uncertainty over whether their personal or professional details have been exposed. On 9 December 2024 the ransomware group apt73 publicly listed bankily.mr as a victim, claiming it had stolen internal files. The number of individuals affected remains unknown, and the precise contents of the material have not been fully confirmed, yet any compromise of banking-related systems carries concrete risks of fraud, identity misuse and further targeting.
What is known so far is limited to the group’s own claim and a brief public summary. No independent verification of the full scale or method has been released, leaving customers, employees and partners to weigh the practical implications for themselves.
Breaking down the breach
According to the listing published by apt73, the organisation bankily.mr suffered a ransomware attack in which internal files were exfiltrated. The incident was reported on 9 December 2024. Public detail stops there: the number of people affected is unknown, the exact date of the intrusion has not been disclosed, and no technical description of how the attackers gained access has been made available. The group’s claim is that data was taken before or during the ransomware encryption phase—a common pattern in modern double-extortion operations—but that assertion has not been independently confirmed by the organisation or by third-party investigators.
The only concrete description released so far states that the material includes employee names and data, among them an administrator’s username. Beyond that truncated note, further specifics remain undisclosed. No ransom demand figure, no sample file counts and no confirmation of whether systems were restored have entered the public record.
The group behind it: apt73
apt73 is a ransomware operation that has appeared on leak sites in recent years, typically advertising stolen data from organisations it claims to have compromised. Like many contemporary ransomware groups, it follows a double-extortion model: encrypting systems while simultaneously copying files and threatening to publish them if payment is not made. Public reporting on the group describes it as opportunistic rather than highly selective, often targeting mid-sized entities across multiple sectors and geographies. Its leak-site posts serve both as pressure on the victim and as advertising for future victims.
In this instance the group has listed bankily.mr and asserted that internal files were taken. That listing constitutes a claim by the attackers; it does not by itself prove the full extent of the intrusion or the accuracy of every detail they may later release. No statements attributed to apt73 beyond the basic listing and the mention of exfiltrated internal files have been provided in the available record for this particular case.
Who is bankily.mr?
bankily.mr is the online presence associated with BANKILY, a mobile banking product offered by Banque Populaire de Mauritanie. The service enables customers in Mauritania to conduct everyday financial transactions from their phones—checking balances, transferring funds, paying bills and managing accounts. As a digital channel of a national bank, it sits at the intersection of retail banking and mobile technology, handling both customer financial data and the internal systems that support those operations.
Organisations of this type routinely maintain employee directories, administrative credentials, transaction logs and customer records. A breach affecting such an entity is consequential because it can touch both the bank’s workforce and the wider population that relies on the mobile platform for financial services. Even when customer account numbers themselves are not confirmed as exposed, the compromise of internal systems can create secondary risks for account holders.
What data was at risk
The publicly reported information states that internal files were exfiltrated in a ransomware attack. The only named categories are employee names and data, including an administrator’s username. No further inventory—customer records, transaction histories, source code, or configuration files—has been confirmed in the available facts. The exact volume and sensitivity of the material therefore remain unconfirmed.
Banks and their mobile-banking platforms typically hold a range of information: staff contact details and credentials, system configuration data, and, in many cases, customer personal and financial identifiers. Because the precise contents of the files claimed by apt73 have not been independently verified or fully itemised, it is not possible to state with certainty which of those categories, if any, were included. Readers should treat any subsequent dumps or screenshots released by the group as claims requiring careful scrutiny rather than established fact.
Why it matters
For employees whose names and administrative credentials may have been taken, the immediate risks include targeted phishing, credential stuffing against other services, and social-engineering attempts that exploit knowledge of internal roles. An exposed administrator username can lower the barrier for further unauthorised access if passwords or multi-factor tokens are weak or reused.
For customers of the BANKILY service the stakes are more diffuse but still real. Even if core account data has not been confirmed as leaked, the mere association of a banking platform with a ransomware listing can increase the volume of fraudulent messages that impersonate the bank. Individuals may also face longer-term identity risks if any personal details later surface. For the organisation itself, the incident raises operational, regulatory and reputational questions that will need to be addressed through forensic investigation, customer communication and any required notifications under applicable law. None of these consequences require sensational language; they follow directly from the nature of the data and the sector involved.
If your data was in this claimed breach
If you are an employee or customer who believes your information may have been among the internal files claimed by apt73, begin with basic hygiene: change passwords on any accounts that share credentials with work systems, enable multi-factor authentication wherever it is available, and treat unsolicited messages that reference the bank or the incident with caution. Monitor financial statements for unexpected activity and consider placing fraud alerts with relevant credit or banking services if you are in a jurisdiction that offers them.
Because the full scope of the exposure remains unconfirmed, it is also useful to check whether your email address has already appeared in other known breach datasets. Free exposure-scan tools can perform that check without requiring payment or extensive personal information, giving you a clearer picture of your overall digital footprint while official details of this incident continue to emerge.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
federalbank.co.in (PART1) Listed by apt73 Ransomware Grouplinebank.co.id Listed by apt73 Ransomware Groupfederalbank.co.in Listed by apt73 Ransomware Groupbri.co.id Listed by apt73 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the bankily.mr Listed by apt73 Ransomware Group →
Publicly posted by apt73 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.